Site settings
These are the four things only a Confluence administrator can do, and they are the ones that save every space administrator repeating themselves. Find them under Confluence settings, Apps, Capable Approval, across four tabs: Teams, Team permissions, Auth tokens and Slack.
#Teams
Create and edit global approval teams, available in every space on the site. See Manage approval teams for the day to day of running them.
Turning on show in all spaces for a team makes it usable everywhere without a space administrator lifting a finger, using these defaults.
Setting | Value when shown in all spaces |
|---|---|
Enabled | ON |
Minimum approvers | The team size |
Minimum rejections | 1 |
Expiry | None |
Publish on approval | OFF |
A team switched on for all spaces cannot then be configured differently per space. If one space needs its own quorum or expiry, leave the team off globally and let that space enable it in Space settings.

#Team permissions
Who may create, edit and delete global teams. Empty by default, which means Confluence administrators only.
The three Confluence administrator groups and your own account are locked into the list and cannot be removed, so it is not possible to lock everybody out of team management.
This list governs global teams only. A space administrator can always manage teams inside their own space, whatever is set here. See Who can do what.

#Auth tokens
Check whether somebody has an authenticator enrolled, see when they set it up, and clear it if they have lost their device. One person at a time.
You can | Notes |
|---|---|
See enrolment status and date | Search by user. |
Clear an enrolment | The person enrols again themselves next time they approve. |
Create an enrolment for somebody | Not possible, deliberately. A signature nobody else could have made is the whole point. |
Clearing an enrolment is not recorded in the approval history, and there are no backup codes. If you are running a regulated space, keep your own log of lost-device resets. See Sign approvals with a code.

#Slack
Connect the site to a Slack workspace and set up channel notifications. What your team actually gets from it is in Slack.
Setting | Default |
|---|---|
Slack connection | Not connected. One workspace per site. |
Slack approval actions | OFF |
Channels | None |
Spaces per channel | None |
Event types per channel | None enabled. Choose from requests, approvals, rejections, comments, status changes and expirations. |
Slack approval actions is the switch that puts Approve and Reject buttons on messages, and it is the one people ask for by name. Invite the Capable bot to a channel before adding it here.

#The approval status banner
The site-wide switch for the banner across the top of pages is off by default. Individual spaces can follow it, force it on, or force it off. Banner states are approved, rejected, in review and expired. See The approval macro for the in-page alternative.

#A few things that catch people out
Global and space level team management are separate permissions. Being a space administrator gives you neither of these tabs.
One Slack workspace per Confluence site. There is no per-space connection.
Requiring a code to approve is a space setting, not a site one. There is no site-wide equivalent.
Show in all spaces is convenient but inflexible. Use it for teams whose rules genuinely never vary.
#Related
Set these four once, and every space inherits them.
